Hi Anders,
this is possible.
But as always in life it depends to how you want to work later (Maintenance & Administration).
Who should create/update the SAP server certificates?
From my point of view there are 3 options:
1.) Create self-signed certificate in SAP ABAP server and perform certificate request (with Microsoft CA)
2.) Beside USER CA install also SAP CA in Secure Login Server and create SAP Server certificates. You can export SAP Server certificates in proper file format (e.g. *.pse)
3.) Create SAP Server certificates with Microsoft CA (but you need to convert to *.pse format)
Best regards,
Frane